Russian authorities have announced the arrest of three people in Moscow, accused of being behind the creation and distribution of Meduza Stealer, one of the most sophisticated data-stealing programs released on the dark web in recent years.

The news was confirmed by Irina Volk , a Russian police general and spokeswoman for the Interior Ministry, in a post on Telegram . The official noted that the operation was carried out by the Department for Combating Cybercrime (UBK) in cooperation with the Astrakhan region police .
“Meduza Stealer”: A cyber theft tool
According to the preliminary investigation, the arrested individuals had developed and started distributing the Meduza Stealer malware about two years ago, via specialized hacker forums. Meduza operated as a “malware-as-a-service” (MaaS), a subscription service model that allowed other cybercriminals to rent it for their own use, in exchange for a fee or percentage of the profits from the attacks.
See also: Ukrainian accused of participating in Conti ransomware attacks
The software was capable of credentials account, passwords, cryptocurrency wallet data, and information stored in victims' browsers. In fact, a particularly dangerous feature allowed it to "revive" expired Chrome cookies, making it easier to take over accounts even when users were logged out.
From “Meduza” to “Aurora”: The same brains behind different malware
Well-known cybersecurity researcher g0njxa, who monitors the evolution of info-stealers on the dark web, reported that the same group was also behind “Aurora Stealer”, another malware-as-a-service that had appeared in 2022. Both programs were considered particularly profitable, as they offered their users ready-made tools for cyber theft, without requiring specialized technical knowledge.
The arrest of this group could be a significant blow to the underground ecosystem of MaaS platforms, which has experienced a huge boom in recent years, turning cybercrime into a “subscription industry”.

Russian “tolerance” and the overthrow of the rule
Russia has traditionally been criticized for its passive stance toward hackers operating within its borders, with the unwritten rule that they do not attack Russian targets. However, in the case of Meduza, it appears that the software's creators broke this "rule.
See also: Kimsuky and Lazarus teams use new tools
As Volk reported, one of the victims of the group's attacks was an institution in the Astrakhan region, from which confidential data was stolen in May 2025. This attack prompted authorities to launch a criminal investigation under Article 273, Part 2 of the Russian Criminal Code, which deals with “creation, use and distribution of malicious programs.
Botnets and parallel businesses
During the investigation, Russian authorities discovered that the arrested individuals were not limited to Meduza Stealer. They had also developed botnet malware, a system that connects infected computers into a single network, allowing remote execution of commands and bypassing the security mechanisms of the target systems.
The existence of this botnet indicates that the group operated at a professional level, with clearly defined roles and goals, more reminiscent of a corporate structure than individual hackers.

A message with multiple recipients
Irina Volk concluded her statement by saying that police are working to identify all accomplices and that further arrests are possible . While this is a rare move by Russia to crack down on cybercrime, analysts believe the case could have political implications – either as a message of “legitimacy” to the West or as an attempt to control the domestic digital underworld .
See also: Researchers create Linux Rootkit that evades detection
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
In any case, the Meduza case reminds us that cybercrime has now escaped the underground and anonymous screens: it operates with corporate logic, global reach and consequences that affect governments, organizations and ordinary citizens.
The “fall” of the creators of Meduza Stealer may just be the beginning of a new era for digital crime — and for those who pursue it.
Source: www.bleepingcomputer.com
